Production Deployment Checklist
Security
-
FONREX_API_KEYset to a random key (echo "frx_live_$(openssl rand -hex 24)");FONREX_AUTH_REQUIREDleft attrue. - Read-only keys (
FONREX_READ_ONLY_API_KEYS) for every client outside the machine: Google Sheets, dashboards, OpenBB. -
POSTGRES_PASSWORDchanged before the first start. - PostgreSQL and Redis published on
127.0.0.1only (the default); the API reachable only through the reverse proxy. - TLS on the reverse proxy, WebSocket upgrade forwarded for
/ws/. -
USAGE_LOG_IPatnoneortruncated. -
.envand database dumps never committed.
Configuration
-
SEC_EDGAR_EMAILset to your own contact address. -
WEB_CONCURRENCY=1. -
FRED_API_KEYset if you use the DCF. - A proxy (
FONREX_PROXY_URL) for the websites that refuse your server's IP, if needed.
Data
- Instruments imported (
import_assets.py) and prices ingested (scripts/ingest_all.py). -
POST /database/cleanupnever run with the defaultdays_to_keep(730) unless you mean to delete eight of the ten ingested years — count first withdry_run. - Daily
pg_dumpbackup of the whole database, restore tested once.
Monitoring
-
/healthanswers,providers.unavailableis empty. -
/health/providersfilled after the first canary run (06:00 UTC by default). - Critical alerts checked regularly:
GET /health/alerts?severity=critical. - Container health check green:
docker compose ps.